Malicious PDF — malware analysis report

Static analysis result for SHA-256 dae6ece038543c59…

MALICIOUS

PDF

17.2 KB Created: 2019-11-07 16:23:08 +00:00 Authoring application: mPDF 5.7
MD5: 298390dd4facf8d94d2b94a14d0bccf6 SHA-1: 5da7bda858f2e4f4a9c14846387d78764a5836a9 SHA-256: dae6ece038543c59afc36a18671ab85d7ad1a677da0e17564e1d655da0553d7a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded URLs, identified as a link farm. While the specific URLs extracted appear benign, the sheer volume and structure suggest a malicious intent, likely for SEO poisoning or to redirect users to malicious content. The ML classifier strongly supports this assessment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9788

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4737737730735739/Beyond-A-Reasonable-Death-Thaddeus-Murfee-Legal-Thriller-2-by-John-Ellsworth.pdf
    • http://cefasfese.4pu.com/5730733735732732/Attorney-at-Large-Thaddeus-Murfee-Legal-Thriller-3-by-John-Ellsworth.pdf
    • http://cefasfese.4pu.com/7731730732731733/Black-Suit-of-Death-1-Endings-and-Beginnings-by-Edward-Ellsworth.pdf
    • http://cefasfese.4pu.com/1733731732733735/Presumption-of-Innocence-David-Brunelle-Legal-Thriller-1-by-Stephen-Penner.pdf
    • http://cefasfese.4pu.com/1733732731738732/A-Patriot-s-Act-Brent-Marks-Legal-Thriller-Series-1-by-Kenneth-Eade.pdf
    • http://cefasfese.4pu.com/8732732735737733/Misst-nkt-f-r-mord-Kindle-County-Legal-Thriller-1-by-Scott-Turow.pdf
    • http://cefasfese.4pu.com/7730730732739736/Death-in-a-Promised-Land-The-Tulsa-Race-Riot-of-1921-by-Scott-Ellsworth.pdf
    • http://cefasfese.4pu.com/5730733735732731/chase-the-bad-baby-by-John-Ellsworth.pdf
    • http://cefasfese.4pu.com/5733732734735730/The-Lawyer-Michael-Gresham-2-by-John-Ellsworth.pdf
    • http://cefasfese.4pu.com/1738733739739735/Reasonable-Doubt-Full-Series-Reasonable-Doubt-1-3-25-by-Whitney-G-.pdf
    • http://cefasfese.4pu.com/2730732735737734/Reasonable-Doubt-Volume-1-Reasonable-Doubt-1-by-Whitney-G-.pdf
    • http://cefasfese.4pu.com/4734736730739739/Reasonable-Doubt-Volume-1-Reasonable-Doubt-1-by-Whitney-G-.pdf
    • http://cefasfese.4pu.com/1734735735731735/Reasonable-Doubt-Volume-2-Reasonable-Doubt-2-by-Whitney-G-.pdf
    • http://cefasfese.4pu.com/4738736739738730/Urgent-Justice-Vigilante-Justice-Thriller-Series-2-5-with-Jack-Lamburt-28K-word-quot-Thriller-Shot-quot-by-John-Etzil.pdf
    • http://cefasfese.4pu.com/5732736732737739/Annie-s-Verdict-Michael-Gresham-7-Annie-the-Profiler-1-by-John-Ellsworth.pdf
    • http://cefasfese.4pu.com/6731730730734734/Legal-Facetiae-Satirical-And-Humorous-by-John-Willock.pdf
    • http://cefasfese.4pu.com/2734732732736739/The-Books-of-Magic-Volume-7-Death-After-Death-by-John-Ney-Rieber.pdf
    • http://cefasfese.4pu.com/1731738736738730736/T-dlicher-Anstoss-Thriller-by-John-McLane.pdf
    • http://cefasfese.4pu.com/3737733734/Cold-A-Joe-Tiplady-Thriller-1-by-John-Sweeney.pdf
    • http://cefasfese.4pu.com/8739739735738730/Braiding-Legal-Orders-Implementing-the-United-Nations-Declaration-on-the-Rights-of-Indigenous-Peoples-by-John-Borrows.pdf
    • http://cefasfese.4pu.com/4734736730739739/Reasonable-Doubt-Volume-1-Reasonable-Doubt-1-